ETSI TR 187 014 V2.1.1 (2009-02)
Telecommunications and Internet converged Services and Protocols for Advanced Networking (TISPAN); eSecurity; User Guide to eTVRA web-database
Telecommunications and Internet converged Services and Protocols for Advanced Networking (TISPAN); eSecurity; User Guide to eTVRA web-database
DTR/TISPAN-07020-NGN-R2
General Information
Standards Content (Sample)
ETSI TR 187 014 V2.1.1 (2009-02)
Technical Report
Telecommunications and Internet converged Services and
Protocols for Advanced Networking (TISPAN);
eSecurity;
User Guide to eTVRA web-database
---------------------- Page: 1 ----------------------
2 ETSI TR 187 014 V2.1.1 (2009-02)
Reference
DTR/TISPAN-07020-NGN-R2
Keywords
data, security
ETSI
650 Route des Lucioles
F-06921 Sophia Antipolis Cedex - FRANCE
Tel.: +33 4 92 94 42 00 Fax: +33 4 93 65 47 16
Siret N° 348 623 562 00017 - NAF 742 C
Association à but non lucratif enregistrée à la
Sous-Préfecture de Grasse (06) N° 7803/88
Important notice
Individual copies of the present document can be downloaded from:
http://www.etsi.org
The present document may be made available in more than one electronic version or in print. In any case of existing or
perceived difference in contents between such versions, the reference version is the Portable Document Format (PDF).
In case of dispute, the reference shall be the printing on ETSI printers of the PDF version kept on a specific network drive
within ETSI Secretariat.
Users of the present document should be aware that the document may be subject to revision or change of status.
Information on the current status of this and other ETSI documents is available at
http://portal.etsi.org/tb/status/status.asp
If you find errors in the present document, please send your comment to one of the following services:
http://portal.etsi.org/chaircor/ETSI_support.asp
Copyright Notification
No part may be reproduced except as authorized by written permission.
The copyright and the foregoing restriction extend to reproduction in all media.
© European Telecommunications Standards Institute 2009.
All rights reserved.
TM TM TM TM
DECT , PLUGTESTS , UMTS , TIPHON , the TIPHON logo and the ETSI logo are Trade Marks of ETSI registered
for the benefit of its Members.
TM
3GPP is a Trade Mark of ETSI registered for the benefit of its Members and of the 3GPP Organizational Partners.
LTE™ is a Trade Mark of ETSI currently being registered
for the benefit of its Members and of the 3GPP Organizational Partners.
GSM® and the GSM logo are Trade Marks registered and owned by the GSM Association.
ETSI
---------------------- Page: 2 ----------------------
3 ETSI TR 187 014 V2.1.1 (2009-02)
Contents
Intellectual Property Rights . 4
Foreword . 4
1 Scope . 5
2 References . 5
2.1 Normative references . 5
2.2 Informative references . 5
3 Definitions and abbreviations . 6
3.1 Definitions . 6
3.2 Abbreviations . 6
4 Overview of eTVRA web application structure . 6
5 User guide . 8
5.1 Access to the eTVRA home page . 8
5.1.1 Access restrictions . 8
5.2 eTVRA step 1 . 9
5.2.1 Creation and editing systems . 9
5.2.2 Creation and editing of objectives . 10
5.2.3 Creation and editing of unwanted incidents . 12
5.3 eTVRA step 2 . 14
5.4 eTVRA step 3 . 15
5.5 eTVRA steps 4, 5, 6 and 7 . 16
5.6 Risk reporting . 21
History . 22
ETSI
---------------------- Page: 3 ----------------------
4 ETSI TR 187 014 V2.1.1 (2009-02)
Intellectual Property Rights
IPRs essential or potentially essential to the present document may have been declared to ETSI. The information
pertaining to these essential IPRs, if any, is publicly available for ETSI members and non-members, and can be found
in ETSI SR 000 314: "Intellectual Property Rights (IPRs); Essential, or potentially Essential, IPRs notified to ETSI in
respect of ETSI standards", which is available from the ETSI Secretariat. Latest updates are available on the ETSI Web
server (http://webapp.etsi.org/IPR/home.asp).
Pursuant to the ETSI IPR Policy, no investigation, including IPR searches, has been carried out by ETSI. No guarantee
can be given as to the existence of other IPRs not referenced in ETSI SR 000 314 (or the updates on the ETSI Web
server) which are, or may be, or may become, essential to the present document.
Foreword
This Technical Report (TR) has been produced by ETSI Technical Committee Telecommunications and Internet
converged Services and Protocols for Advanced Networking (TISPAN).
ETSI
---------------------- Page: 4 ----------------------
5 ETSI TR 187 014 V2.1.1 (2009-02)
1 Scope
The present document is a guide to the use of the ETSI eTVRA web-application.
NOTE: The eTVRA web-application acts as a tool for entering analysis results following completion of an
analysis using the ETSI TVRA method defined in TS 102 165-1 [i.1].
2 References
References are either specific (identified by date of publication and/or edition number or version number) or
non-specific.
• For a specific reference, subsequent revisions do not apply.
• Non-specific reference may be made only to a complete document or a part thereof and only in the following
cases:
- if it is accepted that it will be possible to use all future changes of the referenced document for the
purposes of the referring document;
- for informative references.
Referenced documents which are not found to be publicly available in the expected location might be found at
http://docbox.etsi.org/Reference.
NOTE: While any hyperlinks included in this clause were valid at the time of publication ETSI cannot guarantee
their long term validity.
2.1 Normative references
The following referenced documents are indispensable for the application of the present document. For dated
references, only the edition cited applies. For non-specific references, the latest edition of the referenced document
(including any amendments) applies.
Not applicable.
2.2 Informative references
The following referenced documents are not essential to the use of the present document but they assist the user with
regard to a particular subject area. For non-specific references, the latest version of the referenced document (including
any amendments) applies.
[i.1] ETSI TS 102 165-1: "Telecommunications and Internet converged Services and Protocols for
Advanced Networking (TISPAN); Methods and protocols; Part 1: Method and proforma for
Threat, Risk, Vulnerability Analysis".
[i.2] ETSI TR 187 011: "Telecommunications and Internet converged Services and Protocols for
Advanced Networking (TISPAN); NGN Security; Application of ISO-15408-2 requirements to
ETSI standards - guide, method and application with examples".
[i.3] ISO/IEC 15408-2: " Information technology - Security techniques - Evaluation criteria for IT
security - Part 2: Security functional components".
[i.4] ISO/IEC 15408-1: "Information technology - Security techniques - Evaluation criteria for IT
security - Part 1: Introduction and general model".
[i.5] ISO/IEC 15408-3: "Information technology - Security techniques - Evaluation criteria for IT
security - Part 3: Security assurance components".
ETSI
---------------------- Page: 5 ----------------------
6 ETSI TR 187 014 V2.1.1 (2009-02)
3 Definitions and abbreviations
3.1 Definitions
For the purposes of the present document, the terms and definitions given in TS 102 165-1 [i.1] and TR 187 011 [i.2]
apply.
3.2 Abbreviations
For the purposes of the present document, the following abbreviations apply:
EAL Evaluation Assurance Level
EOL ETSI On Line account
TVRA Threat Vulnerability and Risk Analysis
UML Unified Modelling Language
URL Uniform Resource Locator
4 Overview of eTVRA web application structure
The eTVRA web application is structured as shown in figure 1.
Figure 1: eTVRA web application structure
The web page design is aligned to the "look and feel" of the ETSI Web-application suite and any change to the overall
ETSI look will be reflected in the eTVRA site.
The eTVRA tool and website populates a database, as defined in annex E of TS 102 165-1 [i.1] but modified for
practical implementation on the ETSI server platform. The eTVRA site and database allow cataloguing of the results of
the analysis but does not present any shortcut in the analysis (although it may be possible to modify entries and their
associated risk to view the impact of adding countermeasures to the system).
ETSI
---------------------- Page: 6 ----------------------
7 ETSI TR 187 014 V2.1.1 (2009-02)
Unwanted Incidents
Security Objective
PK,I1 ID
PK,FK1 SecurityObjective
I2 UnwantedIncident
Threat Family
PK,I1 ID
I2 Threat family
Security Objective
Weakness
PK ID
Name
Vulnerablity
Threat Description
Att
...
Questions, Comments and Discussion
Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.